Company Details
pgcps
13,253
33,486
6111
pgcps.org
0
PRI_3244284
In-progress

Prince George's County Public Schools Company CyberSecurity Posture
pgcps.orgPrince George's County Public Schools (PGCPS), one of the nation's 25 largest school districts, has 200 schools and centers, more than 133,000 students and 22,000 employees. The school system serves a diverse student population from urban, suburban and rural communities located in the Washington, DC suburbs. PGCPS is nationally recognized for innovative programs and initiatives that provide students with unique learning opportunities, including arts integration, environmental and financial literacy, and language immersion.
Company Details
pgcps
13,253
33,486
6111
pgcps.org
0
PRI_3244284
In-progress
Between 650 and 699

PGCPS Global Score (TPRM)XXXX

Description: In August, Prince George’s County Public Schools, Maryland’s second-largest school district, detected a cyberattack impacting approximately 4,500 users. While the district's main business and student-information systems remained unaffected, it marked a significant security breach. The school district is collaborating with cybersecurity experts, government officials, and law enforcement to fully understand the scope of the attack. Affected individuals will be contacted, and all users have been instructed to reset their passwords as a precautionary measure.
Description: PGCPS network hit by cyberattack which affected 4,500 accounts. The primary business and student information systems, Oracle and SchoolMAX, do not appear to have been affected, according to the school system, which is still evaluating the scope of the incident. Within the following few days, impacted consumers should hear from a team of outside cybersecurity specialists with more details about their accounts.
Description: On March 12, 2024, the Maine Office of the Attorney General reported a data breach at Prince George’s County Public Schools due to ransomware. The incident affected 117,785 individuals, including 25 Maine residents whose personal information, such as names and financial account information, may have been exposed. Identity theft protection services were offered to affected individuals for 12 months through Experian.


No incidents recorded for Prince George's County Public Schools in 2025.
No incidents recorded for Prince George's County Public Schools in 2025.
No incidents recorded for Prince George's County Public Schools in 2025.
PGCPS cyber incidents detection timeline including parent company and subsidiaries

Prince George's County Public Schools (PGCPS), one of the nation's 25 largest school districts, has 200 schools and centers, more than 133,000 students and 22,000 employees. The school system serves a diverse student population from urban, suburban and rural communities located in the Washington, DC suburbs. PGCPS is nationally recognized for innovative programs and initiatives that provide students with unique learning opportunities, including arts integration, environmental and financial literacy, and language immersion.


The COBB COUNTY SCHOOL DISTRICT is a public school system with administrative offices based at 514 Glover St., Marietta, GA 30060. Cobb County School District (CCSD) is the second largest school system in Georgia. CCSD is responsible for educating more than 112,000 students in a diverse, constantly

The Toronto District School Board (TDSB) is the largest and one of the most diverse school boards in Canada, and recognized by Forbes and Statista as one of Canada's Best Employers for Diversity for 2023. We serve more than 239,000 students in 582 schools throughout Toronto, and more than 100,000 li

New York City Public Schools (NYCPS) is the largest public school system in the United States, serving approximately 1.1 million students across more than 1,600 schools in all five boroughs. Our schools are powered by over 75,000 teachers and thousands of paraprofessionals, school counselors, social

Fairfax County Public Schools (FCPS), located in Northern Virginia, is the nation’s 9th largest public school system, serves a diverse population of more than 180,000 students in grades prekindergarten through 12. Fairfax County high schools are recognized annually by the Washington Post as being am

Montgomery County Public Schools (MCPS), located in Maryland outside of Washington, D.C., is the largest school district in the state. MCPS has 209 schools and serves a diverse population of more than 160,000 students. MCPS offers competitive salaries and benefits, has a nationally recognized prof

Gwinnett County Public Schools (GCPS), located in the metro Atlanta area, is the largest school system in Georgia and the 11th largest school district in the country, offering education professionals and support staff endless opportunities to SHINE. GCPS is one of the nation’s top urban school dist

Hillsborough County Public Schools is the seventh largest school district in the nation, with more than 210,000 students. More than 50,000 students attend a school through one of the district’s many school choice programs. HCPS is the largest employer in Hillsborough County, with more than 24,000 e

The Peel District School Board serves more than 156,000 students in kindergarten to grade 12. Operating more than 257 schools in the municipalities of Brampton, Caledon and Mississauga, the Peel board is the largest employer in Peel. At the Peel board, we inspire success, confidence and hope in ea

Orange County Public Schools is recognized as one of the top urban school districts in the nation – the 8th largest school district in America (4th in Florida) with 210 traditional schools, approximately 206,000 students and over 24,000 employees. OCPS students enjoy equity and access to a wide v
.png)
Maryland's largest counties sit at the center of a national surge in data center development. Demand for cloud services,...
Manassas City Public Schools will reopen Wednesday on a two-hour delay after closing Monday due to a cybersecurity incident.
Manassas City, Virginia, public students won't have classes Monday, following a weekend cyberattack.
MANASSAS, Va. - Manassas City Schools were closed Monday following a cybersecurity incident, officials said.
Manassas City Public Schools will be closed on Monday after the school system experienced a cybersecurity incident over the weekend,...
Manassas City Public Schools are closed on Monday due to a cybersecurity incident that has led to connectivity disruptions and phone outages...
Manassas City Public Schools (MCPS) will be closed on Monday, Nov. 10, due to a cybersecurity incident, MCPS Superintendent Dr. Kevin Newman...
Prince George's County Public Schools warned families this week that there are cases of hand, foot and mouth disease at over 40 schools...
When Fírebamí Babalola arrived at St. John's University from Prince George's County, MD, he sought more than just a degree.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Prince George's County Public Schools is https://www.pgcps.org/.
According to Rankiteo, Prince George's County Public Schools’s AI-generated cybersecurity score is 662, reflecting their Weak security posture.
According to Rankiteo, Prince George's County Public Schools currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Prince George's County Public Schools is not certified under SOC 2 Type 1.
According to Rankiteo, Prince George's County Public Schools does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Prince George's County Public Schools is not listed as GDPR compliant.
According to Rankiteo, Prince George's County Public Schools does not currently maintain PCI DSS compliance.
According to Rankiteo, Prince George's County Public Schools is not compliant with HIPAA regulations.
According to Rankiteo,Prince George's County Public Schools is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Prince George's County Public Schools operates primarily in the Primary and Secondary Education industry.
Prince George's County Public Schools employs approximately 13,253 people worldwide.
Prince George's County Public Schools presently has no subsidiaries across any sectors.
Prince George's County Public Schools’s official LinkedIn profile has approximately 33,486 followers.
Prince George's County Public Schools is classified under the NAICS code 6111, which corresponds to Elementary and Secondary Schools.
No, Prince George's County Public Schools does not have a profile on Crunchbase.
Yes, Prince George's County Public Schools maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/pgcps.
As of November 28, 2025, Rankiteo reports that Prince George's County Public Schools has experienced 3 cybersecurity incidents.
Prince George's County Public Schools has an estimated 7,821 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach, Cyber Attack and Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with team of outside cybersecurity specialists, and third party assistance with cybersecurity experts, and and communication strategy with affected individuals will be contacted, communication strategy with all users have been instructed to reset their passwords as a precautionary measure, and third party assistance with experian..
Title: PGCPS Network Cyberattack
Description: PGCPS network hit by cyberattack which affected 4,500 accounts. The primary business and student information systems, Oracle and SchoolMAX, do not appear to have been affected, according to the school system, which is still evaluating the scope of the incident. Within the following few days, impacted consumers should hear from a team of outside cybersecurity specialists with more details about their accounts.
Type: Cyberattack
Title: Cyberattack on Prince George’s County Public Schools
Description: In August, Prince George’s County Public Schools, Maryland’s second-largest school district, detected a cyberattack impacting approximately 4,500 users.
Date Detected: August
Type: Cyberattack
Title: Prince George’s County Public Schools Data Breach
Description: Unauthorized access to systems due to ransomware affecting 117,785 individuals, including 25 Maine residents.
Date Detected: 2024-03-12
Date Publicly Disclosed: 2024-03-12
Type: Data Breach
Attack Vector: Ransomware
Common Attack Types: The most common types of attacks the company has faced is Breach.

Systems Affected: OracleSchoolMAX

Data Compromised: Names, Financial account information
Identity Theft Risk: High
Payment Information Risk: High
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Financial Account Information and .

Entity Name: PGCPS
Entity Type: Educational Institution
Industry: Education
Customers Affected: 4500

Entity Name: Prince George’s County Public Schools
Entity Type: Educational Institution
Industry: Education
Location: Maryland
Customers Affected: 4500

Entity Name: Prince George’s County Public Schools
Entity Type: Educational Institution
Industry: Education
Location: Prince George’s County
Customers Affected: 117785

Third Party Assistance: Team of outside cybersecurity specialists

Third Party Assistance: cybersecurity experts
Communication Strategy: affected individuals will be contactedall users have been instructed to reset their passwords as a precautionary measure

Third Party Assistance: Experian.
Third-Party Assistance: The company involves third-party assistance in incident response through Team of outside cybersecurity specialists, cybersecurity experts, Experian, .

Type of Data Compromised: Names, Financial account information
Number of Records Exposed: 117785
Sensitivity of Data: High
Personally Identifiable Information: namesfinancial account information

Source: Maine Office of the Attorney General
Date Accessed: 2024-03-12
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2024-03-12.

Investigation Status: Ongoing

Investigation Status: ongoing
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Affected Individuals Will Be Contacted and All Users Have Been Instructed To Reset Their Passwords As A Precautionary Measure.
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Team of outside cybersecurity specialists, cybersecurity experts, Experian, .
Most Recent Incident Detected: The most recent incident detected was on August.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-03-12.
Most Significant Data Compromised: The most significant data compromised in an incident were names, financial account information and .
Most Significant System Affected: The most significant system affected in an incident was OracleSchoolMAX.
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Team of outside cybersecurity specialists, cybersecurity experts, experian, .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were financial account information and names.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 902.0.
Most Recent Source: The most recent source of information about an incident is Maine Office of the Attorney General.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.